Overview
- Bitdefender Antispam Lab publicly documented the campaign in a July 1 report after observing emails that pose as Interpol investigators and point victims to a Proton Drive link.
- The messages include a password and a file named archive.rar so recipients can open a password‑protected multi‑layer archive that ultimately runs an executable disguised as a video.
- The deployed malware encrypts files, drops a ransom note that forbids scanning or moving files, and instructs victims to negotiate through the Tox encrypted messenger without listing a fixed ransom.
- Researchers describe the code as custom and relatively simple, and they say the operation appears smaller and targeted, with victims in Europe, Asia, the Middle East and the United States across multiple sectors.
- Security advice for small businesses includes verifying unsolicited investigative notices out of band, inspecting file extensions before opening, avoiding running unknown executables, and submitting suspicious links or files to scanners such as VirusTotal.